Guides

Google Consent Mode v2: Setup Guide with Code

Updated:

Google Consent Mode v2 tells Google tags whether a visitor agreed to cookies for analytics and ads. Without it, Google does not add visitors from the European Economic Area to your ad audiences. Below is a setup with plain gtag.js that you can copy, plus how to check that it works.

What Consent Mode v2 is

Consent Mode is a set of signals your site sends to Google tags (Google Analytics 4, Google Ads, Floodlight). Each signal is granted or denied, and the tags adjust their behavior to it. Version 2, introduced in November 2023, added two signals about advertising data:

SignalWhat it controls
ad_storageStorage, such as cookies, related to advertising
analytics_storageStorage, such as cookies, related to analytics (for example, visit duration)
ad_user_data (new in v2)Sending user data related to advertising to Google
ad_personalization (new in v2)Personalized advertising, such as remarketing

Who needs it

Since March 2024, Google expects consent signals for visitors in the European Economic Area. If they are missing, those visitors are not added to the audiences used by Google advertising products, and remarketing and personalized ads for them stop working. Both ad_user_data and ad_personalization must be granted for personalized advertising.

If your site has no visitors from Europe and does not run Google Ads, Consent Mode is optional. If you use a Google-certified consent management platform, it most likely sends the signals for you — check its settings first.

Basic or advanced mode

BasicAdvanced
Before the visitor answersGoogle tags are not loaded at allTags load with the default state (usually denied)
If the visitor declinesNothing is sent to GoogleCookieless pings without identifiers are sent
Conversion modelingGeneral modelMore detailed, advertiser-specific model

The code below is the advanced setup: the tags load right away and wait for the answer in the denied state. For basic mode, load the Google tag only after the visitor has accepted.

Step 1. Set the defaults before the Google tag

The default state must be set before the tag sends anything. Put this snippet in the <head> above the Google tag or the Tag Manager snippet:

Defaults: everything denied until the visitor answershtml
<script>
  window.dataLayer = window.dataLayer || [];
  function gtag(){dataLayer.push(arguments);}

  gtag('consent', 'default', {
    ad_storage: 'denied',
    ad_user_data: 'denied',
    ad_personalization: 'denied',
    analytics_storage: 'denied',
    wait_for_update: 500, // ms to wait for a banner that loads asynchronously
  });
</script>

<!-- then the Google tag or the Google Tag Manager snippet -->
<script async src="https://www.googletagmanager.com/gtag/js?id=G-XXXXXXX"></script>
<script>
  gtag('js', new Date());
  gtag('config', 'G-XXXXXXX');
</script>

To deny by default only in some countries, add region with ISO codes — for example region: ['DE', 'FR', 'ES']. Defaults without region apply everywhere else.

Step 2. Send the visitor’s choice

When the visitor clicks a button in your banner, call update. Remember the choice and send it again at the start of every next page view, right after the defaults:

A minimal bannerhtml
<div id="cookie-banner" hidden>
  <p>We use cookies for analytics and ads. Is that fine with you?</p>
  <button type="button" data-choice="granted">Accept</button>
  <button type="button" data-choice="denied">Reject</button>
</div>

<script>
  const KEY = 'cookie_choice';
  const send = (state) => gtag('consent', 'update', {
    ad_storage: state,
    ad_user_data: state,
    ad_personalization: state,
    analytics_storage: state,
  });

  const saved = localStorage.getItem(KEY);
  const banner = document.getElementById('cookie-banner');
  if (saved) send(saved); else banner.hidden = false;

  banner.addEventListener('click', (e) => {
    const state = e.target.dataset.choice;
    if (!state) return;
    localStorage.setItem(KEY, state);
    send(state);
    banner.hidden = true;
  });
</script>

Optional: url_passthrough and ads_data_redaction

Two settings help when ad cookies are denied:

gtag('set', 'url_passthrough', true);     // pass ad click info in links instead of cookies
gtag('set', 'ads_data_redaction', true);  // redact ad click identifiers while ad_storage is denied

If you use Google Tag Manager

In Tag Manager the defaults go into a tag that fires on the Consent Initialization – All Pages trigger, before any other tag. Most consent platforms provide a ready template for this in the Community Template Gallery; the update then comes from the platform when the visitor answers.

How to check that it works

  1. Open your site through Tag Assistant and look at the Consent tab: you should see the default state first and then the update after a click in the banner.
  2. In the browser developer tools, open the Network tab and filter by collect: requests to Google Analytics carry a gcs parameter that changes from G100 (denied) to G111 (granted) after acceptance.
  3. Reload the page after accepting: the saved choice must be sent again without showing the banner.

One banner for Google and your other tools

Consent Mode covers only Google tags. Other scripts on the site need the same answer. The Sitecog widget, for example, has its own consent mode: add data-consent="required" to its tag, and analytics waits for consent while forms and live chat keep working. It does not send Google consent signals, so pass the answer to both from your banner:

Google and Sitecog from one clickhtml
<script src="https://widget.sitecog.com/widget.js" data-consent="required" defer></script>

<script>
  window.crmConsent = window.crmConsent || [];   // a queue: works before widget.js loads

  function applyChoice(state) {
    gtag('consent', 'update', {
      ad_storage: state,
      ad_user_data: state,
      ad_personalization: state,
      analytics_storage: state,
    });
    crmConsent.push(state === 'granted' ? 'grant' : 'deny');
  }
</script>

Frequently asked questions

Is Consent Mode a cookie banner?

No. Consent Mode only passes the visitor’s choice to Google tags. You still need a banner (your own or a consent management platform) that asks the question and calls the update command.

Do I need Consent Mode v2 outside the EEA?

Google requires consent signals for visitors in the European Economic Area. Elsewhere it is optional, but you can still use it — and with the region parameter you can deny by default only for the countries that need it.

What happens when a visitor rejects cookies?

In basic mode the Google tags do not send anything. In advanced mode they send cookieless pings without identifiers, which Google uses for conversion modeling.

Does Consent Mode make my site GDPR compliant?

Not by itself. It respects the choice the visitor made; whether you ask correctly, in time and with clear wording is up to your banner and privacy policy.

Does Sitecog set Google Consent Mode for me?

No. The Sitecog widget has its own consent mode for its analytics and does not send Google consent signals. Connect both to the same banner, as shown in this guide.